Authentication system
The face authentication system simplifies the process of registering facial data across multiple systems by using a user terminal to extract and manage features centrally, enhancing user convenience and reducing repetitive registration.
Patent Information
- Application Number
- JP2025119053
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-07-15
- Publication Date
- 2025-10-22
Smart Images

Figure 2025160254000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an authentication system. [Background technology]
[0002] Conventionally, as a face authentication system that performs authentication based on face data, a face authentication system that performs identity authentication by comparing input face data with pre-registered face data is known (see, for example, Patent Documents 1 and 2).
[0003] The face authentication system described in Patent Document 1 authenticates a target person using an image of the face portion in an image captured by a camera. In addition, the face authentication system described in Patent Document 2, for example, when four face images are registered, two are face patterns for ensuring accuracy, one is a face pattern for absorbing disturbance components, and one is a face pattern to be updated. When a new face pattern is registered, the face pattern to be updated that has the second lowest similarity to the newly registered face pattern is deleted from the four previously registered face patterns. In other words, by leaving the face pattern for absorbing disturbance components that has the lowest similarity to the newly registered face pattern, face authentication is performed while adapting to environmental variations. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 2019-197426 [Patent Document 2] Japanese Patent Application Laid-Open No. 2006-72540 Summary of the Invention [Problem to be solved by the invention]
[0005] Although the provision of an authentication engine using facial recognition is widespread, the facial recognition systems of Patent Documents 1 and 2 cannot perform facial recognition with an authentication engine in which facial data is not registered. Therefore, in order to perform authentication with each of multiple authentication engines, the user must register facial data in each of the multiple authentication engines, which is time-consuming and stressful.
[0006] The present invention has been made in consideration of these points, and aims to improve the convenience of a face recognition platform that uses multiple face recognition engines. [Means for solving the problem]
[0007] The authentication system of the present invention comprises a first imaging means for acquiring and transmitting facial image data of a user for extracting features to be used as a comparison standard; a plurality of facial recognition devices for comparing the user's face with the comparison standard and determining whether or not to provide the service requested by the user; and a service registration means for registering services to be used by the user from among the services provided using each of the facial recognition devices, wherein the first imaging means and the service registration means are provided using a user terminal which is an information terminal carried by the user, and each of the facial recognition devices has a feature extraction means for extracting features from the user's facial image data and a storage device in which the features to be used as the comparison standard are registered.
[0008] The authentication system of the present invention also comprises a first photographing means for acquiring and transmitting facial image data of a user for extracting features to be used as a comparison standard, and a plurality of facial recognition devices for comparing the user's face with the comparison standard and determining whether or not to provide the service requested by the user, each of which has a feature extraction means for extracting features from the facial image data of the user and a storage device in which the features to be used as the comparison standard are registered, and the services include those that can be provided by authenticating the user's face alone and those that require authentication by a method other than biometric authentication in addition to authenticating the user's face. [Effects of the Invention]
[0009] According to the authentication system of the present invention, it is possible to improve the convenience of a face authentication platform that uses multiple face authentication engines. [Brief explanation of the drawings]
[0010] [Figure 1] FIG. 1 is a diagram illustrating an example of a face authentication system according to an embodiment of the present invention and an authentication engine disposed at each service facility. [Figure 2] 2 is a flowchart showing the processing content executed when registering a face image of a user by the face authentication system shown in FIG. 1. [Figure 3] 2 is a flowchart showing an example of processing content executed when authenticating a user by the authentication engine and face authentication system shown in FIG. 1. [Figure 4] FIG. 10 is a diagram illustrating another example of a face authentication system and an authentication engine disposed at each service center according to an embodiment of the present invention. [Figure 5] 5 is a flowchart showing the processing content executed when registering a face image of a user by the face authentication system shown in FIG. 4. [Figure 6] 5 is a flowchart showing an example of processing content executed when authenticating a user by the authentication engine and face authentication system shown in FIG. 4. [Figure 7] FIG. 10 is a diagram illustrating yet another example of a face authentication system and an authentication engine disposed at each service center according to an embodiment of the present invention. [Figure 8] 8 is a flowchart showing the processing content executed when the face authentication system shown in FIG. 7 registers a face image of a user. [Figure 9] 8 is a flowchart showing an example of processing content executed when authenticating a user by the authentication engine and face authentication system shown in FIG. 7. [Figure 10] FIG. 10 is a diagram showing an initial screen displayed on a user terminal. [Figure 11]FIG. 10 is a diagram showing a registration screen displayed on a user terminal. [Figure 12] FIG. 10 is a diagram showing a registration screen displayed on a user terminal. [Figure 13] FIG. 10 is a diagram showing a service addition screen displayed on a user terminal. [Figure 14] FIG. 10 is a diagram showing an authentication history screen displayed on a user terminal. [Figure 15] FIG. 10 is a diagram showing a detailed screen of an authentication history displayed on a user terminal. [Figure 16] FIG. 10 is a diagram illustrating another example of a face authentication system according to an embodiment of the present invention and an authentication engine disposed in each company. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. Figures 1 to 15 are diagrams showing a face authentication system according to this embodiment and authentication engines arranged in each service facility.
[0012] As shown in FIG. 1, authentication engines 30A, 30B, and 30C that authenticate users are installed in each service facility, such as a restaurant, hotel, transportation facility, office building, apartment complex, or convenience store. Although FIG. 1 illustrates three authentication engines 30A, 30B, and 30C, two or more authentication engines may be used. A facial authentication system 10 installed in a company separate from each service facility is communicatively connected to each authentication engine 30A, 30B, and 30C via a network such as the Internet. A user terminal 20, such as a smartphone owned by a user, is communicatively connected to the facial authentication system 10 and each authentication engine 30A, 30B, and 30C via a network such as the Internet. Details of the facial authentication system 10 and each authentication engine 30A, 30B, and 30C are described below.
[0013] The facial authentication system 10 is configured, for example, by a computer, and includes a processor 12 such as a CPU, a memory 16, and a communication unit 18. The processor 12 includes a feature extraction means 14 that extracts features of a user's facial image corresponding to each authentication engine 30A, 30B, and 30C as hash values based on facial image data received from a user terminal 20, and a registration means 13 that registers the extracted features of the user's facial image. The processor 12 executes a program stored in the memory 16 to cause the feature extraction means 14 to extract features of the user's facial image corresponding to each authentication engine 30A, 30B, and 30C as hash values. Specifically, the feature extraction means 14 extracts hash values calculated from the received user's facial image data using a predetermined hash function as the features of the user's facial image. Note that even if the user's facial image data is the same, the features of the user's facial image may differ depending on the type of authentication engine 30A, 30B, and 30C. This is because the specifications of the authentication engines 30A, 30B, and 30C used by different service providers, such as business companies, are different. Therefore, the feature extraction means 14 extracts features of the user's facial image for each of the authentication engines 30A, 30B, and 30C. That is, from one facial image data, feature amounts of multiple users' facial images corresponding to each of the authentication engines 30A, 30B, and 30C are extracted. Furthermore, by executing a program stored in the memory 16, the processor 12 causes the registration means 13 to associate the feature amounts (specifically, hash values) of the user's facial image for each of the authentication engines 30A, 30B, and 30C extracted by the feature extraction means 14 with the user's identification information and the identification information of the authentication engines 30A, 30B, and 30C and store them in the memory 16. The program executed by the processor 12 is not limited to the program stored in the memory 16. Processing may be performed in each of the feature extraction means 14 and the registration means 13 by the processor 12 executing a program transmitted to the face authentication system 10 from an external device or a program stored on a recording medium that is detachably attached to the face authentication system 10.
[0014] As described above, the memory 16 stores the feature amounts (specifically, hash values) of the user's facial image extracted by the feature amount extraction means 14 in association with the user's identification information and the identification information of the authentication engines 30A, 30B, and 30C. As described above, the feature amounts of the user's facial image extracted by the feature amount extraction means 14 may differ depending on the type of authentication engine 30A, 30B, and 30C. For this reason, the feature amount extraction means 14 extracts the feature amounts of the user's facial image for each of the authentication engines 30A, 30B, and 30C. As a result, the feature amounts of the user's facial image extracted by the feature amount extraction means 14 must also be stored in the memory 16 in association with each of the authentication engines 30A, 30B, and 30C. The memory 16 also stores the user's identification information in association with the service provider selected by the user. As described above, the memory 16 also stores programs for causing the processor 12 to perform various processes. The processor 12 also transmits and receives signals to and from the authentication engines 30A, 30B, 30C or the user terminal 20 located at each service facility via a communication unit 18 via a network such as the Internet.
[0015] Each of the authentication engines 30A, 30B, and 30C arranged in each service facility is composed of, for example, a computer, and each of the authentication engines 30A, 30B, and 30C has a processor 32A, 32B, or 32C such as a CPU, a memory 36A, 36B, or 36C, an imaging unit 38A, 38B, or 38C, a processing unit 40A, 40B, or 40C, and a communication unit 42A, 42B, or 42C. The processors 32A, 32B, and 32C each have a feature extraction unit 34A, 34B, or 34C that extracts features of a user's facial image as a hash value based on the user's facial image data captured by the imaging unit 38A, 38B, or 38C, and an authentication unit 35A, 35B, or 35C. The processors 32A, 32B, and 32C execute programs stored in memories 36A, 36B, and 36C to cause feature extraction means 34A, 34B, and 34C to extract features of the user's facial image as hash values. Specifically, the feature extraction means 34A, 34B, and 34C extract hash values calculated from the received user's facial image data using a predetermined hash function as features of the user's facial image. The processors 32A, 32B, and 32C also execute programs stored in memories 36A, 36B, and 36C to perform user authentication in authentication means 35A, 35B, and 35C. Details of this processing will be described later. Note that the programs executed by the processors 32A, 32B, and 32C are not limited to those stored in memories 36A, 36B, and 36C. Various processes may be performed in the feature extraction means 34A, 34B, 34C and the authentication means 35A, 35B, 35C by the processors 32A, 32B, 32C executing a program transmitted to the authentication engines 30A, 30B, 30C from an external device or a program stored on a recording medium detachably attached to the authentication engines 30A, 30B, 30C. Furthermore, each of the authentication engines 30A, 30B, 30C is not limited to corresponding to a single service provider. For example, the authentication engine 30A may correspond to multiple service providers.
[0016] The memories 36A, 36B, and 36C are configured to store pre-registered user identification information and facial image features of the users in association with each other. As described above, the memories 36A, 36B, and 36C are configured to store programs for causing the processors 32A, 32B, and 32C to perform various processes. The imaging units 38A, 38B, and 38C each have a camera, for example, and are configured to capture an image of the user to acquire facial image data of the user.
[0017] Furthermore, the processing units 40A, 40B, and 40C are configured to perform various processes for authenticated users. For example, if the authentication engines 30A, 30B, and 30C are installed in an office building or an apartment complex, the processing units 40A, 40B, and 40C unlock doors at entrances and exits of the building or apartment complex when a user is authenticated. Furthermore, if the authentication engines 30A, 30B, and 30C are installed in restaurants, hotels, transportation facilities, convenience stores, and other facilities, they enable cashless payment when paying fees at these service facilities. In this case, the authentication engines 30A, 30B, and 30C transmit payment information to a server of a financial institution or credit card company, so that the payment amount is automatically debited from the user's bank account or added to the credit card statement. Furthermore, the processors 32A, 32B, and 32C transmit and receive signals to and from the face authentication system 10 or the user terminal 20 via a network such as the Internet via the communication units 42A, 42B, and 42C.
[0018] Furthermore, in each authentication engine 30A, 30B, 30C, a user's facial image is captured by the imaging units 38A, 38B, 38C, and the feature quantities of the user's facial image can be registered in each authentication engine 30A, 30B, 30C. Specifically, when the feature quantities of the user's facial image are registered in each authentication engine 30A, 30B, 30C, when the user's facial image is captured by the imaging units 38A, 38B, 38C, the processors 32A, 32B, 32C extract the feature quantities of the user's facial image as hash values using feature extraction means 34A, 34B, 34C based on the user's facial image data captured by the imaging units 38A, 38B, 38C. The extracted feature quantities of the user's facial image (specifically, hash values) are then stored in memories 36A, 36B, 36C. In this manner, the feature quantities of the user's facial image are registered in each authentication engine 30A, 30B, 30C.
[0019] A facial recognition app can be installed on the user terminal 20 from an online store or the like. Once such a facial recognition app is installed, the user can register facial image data and register the service provider from which the service is to be used, using the user terminal 20. The processing content of such a facial recognition app will be described later. Note that such a facial recognition app may be provided by the facial recognition system 10, or may be provided by a system separate from the facial recognition system 10.
[0020] In this embodiment, the face authentication system 10 and the authentication engines 30A, 30B, and 30C arranged in each service facility are API-linked (Application Programming Interface), which makes it easier to configure each of the authentication engines 30A, 30B, and 30C systems than if each of the authentication engines 30A, 30B, and 30C systems were configured independently.
[0021] Next, the processing contents when authenticating a user by the face authentication system 10 and the authentication engines 30A, 30B, and 30C will be described with reference to FIGS. 2, 3, and 10 to 12. FIG.
[0022] First, a process in which a user registers facial image data in the face authentication system 10 using the user terminal 20 will be described. First, the user installs a facial authentication app in the user terminal 20. The initial screen of such a facial authentication app is displayed as shown in FIG. 10. The user first registers using such a facial authentication app on the user terminal 20. Specifically, when the user presses the account button on the screen shown in FIG. 10, a user registration screen such as that shown in FIG. 11 appears. When the user enters registration information such as name, date of birth, phone number, email address, and password on such a user registration screen, checks the box indicating agreement to the terms of use, and then presses the registration button, a facial image capture screen such as that shown in FIG. 12 appears. When the user captures a facial image using the user terminal 20 on such a capture screen, the various information entered on the user registration screen and the user's facial image data are transmitted from the user terminal 20 to the face authentication system 10. In this manner, the processor 12 of the face authentication system 10 receives the facial image data from the user terminal 20 (STEP 1). The processor 12 of the face authentication system 10 also receives from the user terminal 20 the identification information of the user terminal 20, and the registration information such as the user's name, date of birth, telephone number, email address, and password entered into the user terminal 20. The processor 12 also issues a user ID as the user's identification information, and stores the issued user ID in the memory 16.
[0023] Next, the processor 12 of the face authentication system 10 extracts facial image features corresponding to each authentication engine 30A, 30B, and 30C as hash values using the feature extraction means 14 based on the facial image data received from the user terminal 20 (STEP 2). At this time, the feature extraction means 14 may extract different facial image features for each authentication engine 30A, 30B, and 30C. For this reason, the feature extraction means 14 extracts the facial image features of the user for each authentication engine 30A, 30B, and 30C. The feature extraction means 14 also extracts only the facial image features of the user corresponding to the authentication engines 30A, 30B, and 30C of the service facility pre-selected by the user. For example, if the user is permitted to use facial image data for the service facility where authentication engine 30A is installed but is not permitted to use facial image data for the service facility where authentication engine 30B is installed, the feature extraction means 14 extracts only the facial image features of the user corresponding to authentication engine 30A. As described above, the memory 16 stores the user's identification information and the service provider selected by the user in association with each other. The processor 12 then causes the registration means 13 to store the facial image features extracted by the feature extraction means 14 and corresponding to each authentication engine 30A, 30B, and 30C in the memory 16 of the face authentication system 10 in association with the user ID (user's identification information) and the identification information of the authentication engines 30A, 30B, and 30C (STEP 3). This completes the registration of the user's facial image captured by the user terminal 20. Furthermore, the information related to the user's facial image features stored in the memory 16 is transmitted from the face authentication system 10 to the authentication engines 30A, 30B, and 30C of the service provider selected by the user (STEP 4). At this time, the user's facial image features corresponding to these authentication engines 30A, 30B, and 30C are transmitted to the authentication engines 30A, 30B, and 30C. The authentication engines 30A, 30B, and 30C store information relating to the feature amounts of the user's face image transmitted from the face authentication system 10 in memories 36A, 36B, and 36C in association with the user's identification information.
[0024] Next, a process for authenticating a user in each of the authentication engines 30A, 30B, and 30C will be described. When user authentication is required at a service facility where each of the authentication engines 30A, 30B, and 30C is installed, first, the imaging units 38A, 38B, and 38C of the authentication engines 30A, 30B, and 30C capture an image of the user to obtain facial image data of the user (STEP 11). Then, in the authentication engines 30A, 30B, and 30C, the processors 32A, 32B, and 32C extract features of the user's facial image as hash values using feature extraction means 34A, 34B, and 34C based on the acquired facial image data (STEP 12). The processors 32A, 32B, and 32C then compare the features (specifically, hash values) of the user's facial image extracted by the feature extraction means 34A, 34B, and 34C with the features (specifically, hash values) of the user's facial image stored in the memories 36A, 36B, and 36C to authenticate the user (STEP 13). More specifically, if the match rate between the features of the user's facial image extracted by the feature extraction means 34A, 34B, and 34C and the features of the user's facial image stored in the memories 36A, 36B, and 36C exceeds a predetermined threshold (e.g., 80%), the authentication means 35A, 35B, and 35C authenticates the user. As described above, the memories 36A, 36B, and 36C store pre-registered user identification information and the features of the user's facial image in association with each other.
[0025] When the authentication means 35A, 35B, and 35C authenticate the user ("YES" in STEP 14), the processors 32A, 32B, and 32C enable the respective processing units 40A, 40B, and 40C to execute the service corresponding to the authentication engine 30A, 30B, and 30C (STEP 15). Specifically, as described above, when the authentication engines 30A, 30B, and 30C are installed in an office building or an apartment complex, the processing units 40A, 40B, and 40C unlock doors at entrances and exits of the office building or apartment complex when the user is authenticated. Furthermore, when the authentication engines 30A, 30B, and 30C are installed in restaurants, hotels, transportation facilities, convenience stores, and the like, they enable cashless payment when paying fees at these service facilities. Note that when cashless payment is performed, two-step authentication may be performed. Thereafter, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit information related to the usage status of the service to the face authentication system 10 (STEP 17). As a result, information related to the usage status of the service at each service provider is stored in the memory 16 for each user in the face authentication system 10.
[0026] On the other hand, if the features of the user's facial image extracted by the feature extraction means 34A, 34B, 34C do not substantially match the features of the user's facial image stored in the memories 36A, 36B, 36C and the authentication means 35A, 35B, 35C are unable to authenticate the user ("NO" in STEP 14), the processors 32A, 32B, 32C disable the service corresponding to the authentication engine 30A, 30B, 30C using the respective processing units 40A, 40B, 40C (STEP 16). In this case as well, the processors 32A, 32B, 32C of the authentication engines 30A, 30B, 30C transmit information relating to the service usage status (specifically, information that the user attempted to be authenticated by the authentication engine 30A, 30B, 30C but was not authenticated and was therefore unable to use the service) to the face authentication system 17 (STEP 17).
[0027] According to this authentication method, even if the features of a user's facial image are registered in an authentication engine of one service facility (e.g., authentication engine 30A) but not in an authentication engine of another service facility (e.g., authentication engine 30B), by storing the features of the user's facial image in association with the identification information of the authentication engines 30A, 30B, and 30C in memory 16 of face authentication system 10 and memories 36A, 36B, and 36C of each authentication engine 30A, 30B, and 30C, it is possible for a service facility that does not have the features of the user's facial image registered to authenticate the user by capturing the user's facial image with an imaging unit. In this case, the user does not need to register facial image data in all of the multiple authentication engines, thereby saving the user effort.
[0028] It should be noted that the face authentication system 10 and face authentication method according to this embodiment are not limited to those shown in Figures 1 to 3. Other examples of the face authentication system 10 and face authentication method according to this embodiment will be described with reference to Figures 4 to 6. It should be noted that in the face authentication system 10 and each of the authentication engines 30A, 30B, and 30C shown in Figure 4, the same components as those in the face authentication system 10 and each of the authentication engines 30A, 30B, and 30C shown in Figure 1 will be assigned the same reference numerals, and their description will be omitted.
[0029] 4, the processor 12 of the face authentication system 10 includes a feature extraction means 14 that extracts features of the user's face image corresponding to each of the authentication engines 30A, 30B, and 30C as hash values based on the face image data received from the user terminal 20, a registration means 13 that registers the extracted features of the user's face image, and an authentication means 15 that authenticates the user based on the features (specifically, hash values) of the user's face image captured by the imaging units 38A to 38C of each of the authentication engines 30A, 30B, and 30C. The processor 12 executes a program stored in the memory 16 to store in the memory 16 the features (specifically, hash values) of the user's face image extracted by the feature extraction means 14 in the registration means 13 in association with the user's identification information and the identification information of the authentication engines 30A, 30B, and 30C. Moreover, the processor 12 executes a program stored in the memory 16, thereby causing the authentication means 15 to compare the feature amounts (specifically, hash values) of the user's facial image captured by the imaging units 38A to 38C of each of the authentication engines 30A, 30B, and 30C with the feature amounts (specifically, hash values) of the user's facial image corresponding to each of the authentication engines 30A, 30B, and 30C stored in the memory 16, thereby authenticating the user. Note that the programs executed by the processor 12 are not limited to those stored in the memory 16. The processor 12 may execute a program transmitted to the face authentication system 10 from an external device or a program stored in a recording medium detachably attached to the face authentication system 10, thereby performing processing in each of the feature amount extraction means 14, the registration means 13, and the authentication means 15.
[0030] Each of the authentication engines 30A, 30B, and 30C installed at each service facility is composed of, for example, a computer, and each authentication engine 30A, 30B, and 30C includes a processor 32A, 32B, or 32C such as a CPU, a memory 36A, 36B, or 36C, an imaging unit 38A, 38B, or 38C, a processing unit 40A, 40B, or 40C, and a communication unit 42A, 42B, or 42C. The processors 32A, 32B, and 32C include feature extraction means 34A, 34B, or 34C that extracts features of a user's facial image as a hash value based on the user's facial image data captured by the imaging unit 38A, 38B, or 38C. In the example shown in FIG. 4, the processors 32A, 32B, and 32C do not include authentication means 35A, 35B, or 35C as shown in FIG. 1. The processors 32A, 32B, and 32C execute programs stored in the memories 36A, 36B, and 36C to cause the feature extraction means 34A, 34B, and 34C to extract features of the user's facial image as hash values. Specifically, the feature extraction means 34A, 34B, and 34C extract hash values calculated from the received user's facial image data using a predetermined hash function as features of the user's facial image. Note that the programs executed by the processors 32A, 32B, and 32C are not limited to those stored in the memories 36A, 36B, and 36C. The processors 32A, 32B, and 32C may execute programs transmitted to the authentication engines 30A, 30B, and 30C from an external device or programs stored on a recording medium detachably attached to the authentication engines 30A, 30B, and 30C, thereby causing the feature extraction means 34A, 34B, and 34C to perform various processes. In the example shown in FIG. 4, the memories 36A, 36B, and 36C are not configured to store the feature amounts of the user's facial image.
[0031] 4, the face authentication system 10 and the authentication engines 30A, 30B, and 30C arranged in each service facility are API-linked (application programming interface), which makes it easier to configure each of the authentication engines 30A, 30B, and 30C compared to systems where each of the authentication engines 30A, 30B, and 30C is configured independently.
[0032] Next, the processing contents when authenticating a user using the face authentication system 10 and the authentication engines 30A, 30B, and 30C as shown in FIG. 4 will be described with reference to FIGS.
[0033] First, a process in which a user registers facial image data in the face authentication system 10 using the user terminal 20 will be described. A specific method for capturing a facial image using the user terminal 20 has already been described, and will not be described here. When a user first registers using such a face authentication app on the user terminal 20, various information entered on the user registration screen and the user's facial image data are transmitted from the user terminal 20 to the face authentication system 10. In this manner, the processor 12 of the face authentication system 10 receives the facial image data from the user terminal 20 (STEP 21). The processor 12 of the face authentication system 10 also receives, from the user terminal 20, identification information for the user terminal 20 and registration information such as the user's name, date of birth, telephone number, email address, and password entered into the user terminal 20. The processor 12 also issues a user ID as identification information for the user and stores the issued user ID in memory 16.
[0034] Next, the processor 12 of the face authentication system 10 causes the feature extraction means 14 to extract, as hash values, feature amounts of the face image corresponding to each of the authentication engines 30A, 30B, and 30C based on the face image data received from the user terminal 20 (STEP 22). At this time, the feature amounts of the user's face image extracted by the feature extraction means 14 may differ depending on the type of authentication engine 30A, 30B, and 30C, and the feature extraction means 14 extracts feature amounts of the user's face image for each of the authentication engines 30A, 30B, and 30C. In addition, the feature extraction means 14 extracts only feature amounts of the user's face image corresponding to the authentication engines 30A, 30B, and 30C of the service provider pre-selected by the user. Then, the processor 12 causes the registration means 13 to store the features of the facial image corresponding to each authentication engine 30A, 30B, 30C extracted by the feature extraction means 14 in the memory 16 of the face authentication system 10 in association with the user ID (user identification information) and the identification information of the authentication engines 30A, 30B, 30C (STEP 23). In this manner, the registration of the user's facial image captured by the user terminal 20 is completed. Note that in the example shown in Fig. 4, information related to the features of the user's facial image stored in the memory 16 is not transmitted from the face authentication system 10 to the authentication engines 30A, 30B, 30C of the service provider selected by the user.
[0035] Next, a process for authenticating a user in each authentication engine 30A, 30B, and 30C will be described. When user authentication is required at a service facility where each authentication engine 30A, 30B, and 30C is installed, first, the image capturing units 38A, 38B, and 38C of the authentication engines 30A, 30B, and 30C capture an image of the user to acquire facial image data of the user (STEP 31). Furthermore, in the authentication engines 30A, 30B, and 30C, the processors 32A, 32B, and 32C extract features of the user's facial image as hash values using the feature extraction units 34A, 34B, and 34C based on the acquired facial image data (STEP 32). The processors 32A, 32B, and 32C then transmit the features (specifically, hash values) of the user's facial image extracted by the feature extraction units 34A, 34B, and 34C to the processor 12 of the face authentication system 10 via the communication units 42A, 42B, and 42C (STEP 33). When the processor 12 of the face authentication system 10 receives information related to the features of the user's face image from the authentication engines 30A, 30B, and 30C, the processor 12 receives information related to the features of the user's face image transmitted only from the authentication engines 30A, 30B, and 30C of the service provider selected by the user, which is stored in the memory 16. In the face authentication system 10, the processor 12 authenticates the user by comparing the features (specifically, hash values) of the user's face image received from the authentication engines 30A, 30B, and 30C with the features (specifically, hash values) of the user's face image stored in the memory 16 using the authentication means 15 (STEP 34). More specifically, if the match rate between the features of the user's face image received from the authentication engines 30A, 30B, and 30C and the features of the user's face image stored in the memory 16 exceeds a predetermined threshold (e.g., 80%), the authentication means 15 authenticates the user. As described above, the memory 16 stores pre-registered user identification information and identification information of the authentication engines 30A, 30B, and 30C in association with feature amounts of the user's facial image.
[0036] Then, when the authentication means 15 authenticates the user ("YES" in STEP 35), information related to the authentication result is transmitted from the processor 12 of the face authentication system 10 to the authentication engines 30A, 30B, and 30C via the communication unit 18 (STEP 36). Then, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C that have received the information related to the authentication result enable the respective processing units 40A, 40B, and 40C to implement the services corresponding to the authentication engines 30A, 30B, and 30C (STEP 37). Thereafter, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit information related to the usage status of the services to the face authentication system 10. As a result, information related to the usage status of services at each service provider is stored in the memory 16 for each user in the face authentication system 10.
[0037] On the other hand, if the feature amounts of the user's facial image received from the authentication engines 30A, 30B, 30C do not substantially match the feature amounts of the user's facial image stored in the memory 16 and the authentication means 15 is unable to authenticate the user ("NO" in STEP 35), information relating to the authentication result is sent from the processor 12 of the face authentication system 10 to the authentication engines 30A, 30B, 30C via the communication unit 18 (STEP 38). Then, the processors 32A, 32B, 32C of the authentication engines 30A, 30B, 30C that have received the information relating to the authentication result disable the implementation of the service corresponding to the authentication engine 30A, 30B, 30C via the respective processing units 40A, 40B, 40C (STEP 39). In this case, too, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit information regarding the usage status of the service (specifically, information that the user attempted to be authenticated by the authentication engines 30A, 30B, and 30C but was not authenticated and was unable to use the service) to the face authentication system 10.
[0038] According to this authentication method, even if the features of a user's facial image are registered in an authentication engine of one service facility (e.g., authentication engine 30A) but not in an authentication engine of another service facility (e.g., authentication engine 30B), by storing the features of the user's facial image in association with the identification information of authentication engines 30A, 30B, and 30C in memory 16 of face authentication system 10, even a service facility that does not have the features of the user's facial image registered can authenticate the user by capturing the user's facial image with an imaging unit. In this case, the user does not need to register facial image data in all of the multiple authentication engines, thereby saving the user effort.
[0039] Further, still other examples of the face authentication system 10 and face authentication method according to the present embodiment will be described with reference to Figures 7 to 9. Note that, in the face authentication system 10 and the respective authentication engines 30A, 30B, and 30C shown in Figure 7, the same components as those in the face authentication system 10 and the respective authentication engines 30A, 30B, and 30C shown in Figures 1 and 4 will be assigned the same reference numerals, and their description will be omitted.
[0040] 7, the processor 12 of the face authentication system 10 includes a feature extraction means 14 that extracts features of the user's face image corresponding to each of the authentication engines 30A, 30B, and 30C as hash values based on the face image data received from the user terminal 20, a registration means 13 that registers the extracted features of the user's face image, and an authentication means 15 that authenticates the user based on the features (specifically, hash values) of the user's face image captured by the imaging units 38A to 38C of each of the authentication engines 30A, 30B, and 30C. The processor 12 executes a program stored in the memory 16 to store in the memory 16 the features (specifically, hash values) of the user's face image extracted by the feature extraction means 14 in the registration means 13 in association with the user's identification information and the identification information of the authentication engines 30A, 30B, and 30C. Moreover, the processor 12 executes a program stored in the memory 16, thereby causing the authentication means 15 to compare the feature amounts (specifically, hash values) of the user's facial image captured by the imaging units 38A to 38C of each of the authentication engines 30A, 30B, and 30C with the feature amounts (specifically, hash values) of the user's facial image corresponding to each of the authentication engines 30A, 30B, and 30C stored in the memory 16, thereby authenticating the user. Note that the programs executed by the processor 12 are not limited to those stored in the memory 16. The processor 12 may execute a program transmitted to the face authentication system 10 from an external device or a program stored in a recording medium detachably attached to the face authentication system 10, thereby performing processing in each of the feature amount extraction means 14, the registration means 13, and the authentication means 15.
[0041] Each of the authentication engines 30A, 30B, and 30C installed at each service facility is composed of, for example, a computer. Each of the authentication engines 30A, 30B, and 30C includes a processor 32A, 32B, or 32C such as a CPU, a memory 36A, 36B, or 36C, an imaging unit 38A, 38B, or 38C, a processing unit 40A, 40B, or 40C, and a communication unit 42A, 42B, or 42C. The processors 32A, 32B, and 32C include feature extraction means 34A, 34B, or 34C that extracts features of a user's facial image as a hash value based on the user's facial image data captured by the imaging unit 38A, 38B, or 38C. Note that in the example shown in FIG. 7, the processors 32A, 32B, and 32C do not include the feature extraction means 34A, 34B, or 34C and the authentication means 35A, 35B, or 35C shown in FIG. 1. In the example shown in FIG. 7, the memories 36A, 36B, and 36C are not configured to store the feature amounts of the user's facial image.
[0042] 7, the face authentication system 10 and the authentication engines 30A, 30B, and 30C arranged in each service facility are API-linked (application programming interface), which makes it easier to configure each of the authentication engines 30A, 30B, and 30C compared to systems where each of the authentication engines 30A, 30B, and 30C is configured independently.
[0043] Next, the processing contents when authenticating a user using the face authentication system 10 and the authentication engines 30A, 30B, and 30C as shown in FIG. 7 will be described with reference to FIGS.
[0044] First, a process in which a user registers facial image data in the face authentication system 10 using the user terminal 20 will be described. A specific method for capturing a facial image using the user terminal 20 has already been described, and will not be described here. When a user first registers using such a face authentication app on the user terminal 20, various information entered on the user registration screen and the user's facial image data are transmitted from the user terminal 20 to the face authentication system 10. In this manner, the processor 12 of the face authentication system 10 receives the facial image data from the user terminal 20 (STEP 41). The processor 12 of the face authentication system 10 also receives, from the user terminal 20, identification information for the user terminal 20 and registration information such as the user's name, date of birth, telephone number, email address, and password entered into the user terminal 20. The processor 12 also issues a user ID as identification information for the user and stores the issued user ID in memory 16.
[0045] Next, the processor 12 of the face authentication system 10 causes the feature extraction means 14 to extract, as hash values, feature amounts of the face image corresponding to each of the authentication engines 30A, 30B, and 30C based on the face image data received from the user terminal 20 (STEP 42). At this time, the feature amounts of the user's face image extracted by the feature extraction means 14 may differ depending on the type of authentication engine 30A, 30B, and 30C, and the feature extraction means 14 extracts feature amounts of the user's face image for each of the authentication engines 30A, 30B, and 30C. In addition, the feature extraction means 14 extracts only feature amounts of the user's face image corresponding to the authentication engines 30A, 30B, and 30C of the service provider pre-selected by the user. Then, the processor 12 causes the registration means 13 to store the features of the facial image corresponding to each authentication engine 30A, 30B, 30C extracted by the feature extraction means 14 in the memory 16 of the face authentication system 10 in association with the user ID (user identification information) and the identification information of the authentication engines 30A, 30B, 30C (STEP 43). In this manner, the registration of the user's facial image captured by the user terminal 20 is completed. Note that in the example shown in Fig. 7, information related to the features of the user's facial image stored in the memory 16 is not transmitted from the face authentication system 10 to the authentication engines 30A, 30B, 30C of the service provider selected by the user.
[0046] Next, a process for authenticating a user in each of the authentication engines 30A, 30B, and 30C will be described. When user authentication is required at a service facility where each of the authentication engines 30A, 30B, and 30C is installed, first, the user's face image data is acquired by capturing an image of the user using the imaging units 38A, 38B, and 38C of the authentication engines 30A, 30B, and 30C (STEP 51). The processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit the user's face image data captured by the imaging units 38A, 38B, and 38C to the processor 12 of the face authentication system 10 via the communication units 42A, 42B, and 42C (STEP 52). When processor 12 of face authentication system 10 receives the user's facial image data from authentication engines 30A, 30B, and 30C, it receives only the user's facial image data transmitted from authentication engines 30A, 30B, and 30C of the service provider selected by the user, which is stored in memory 16. In face authentication system 10, processor 12 extracts features of the user's facial image as hash values using feature extraction means 14 based on the facial image data received from authentication engines 30A, 30B, and 30C (STEP 53). Processor 12 then authenticates the user by comparing, using authentication means 15, the features of the user's facial image extracted by feature extraction means 14 (specifically, the hash values) with the features of the user's facial image stored in memory 16 (STEP 54). More specifically, if the matching rate between the feature amounts of the user's facial image extracted by the feature amount extraction means 14 and the feature amounts of the user's facial image stored in the memory 16 exceeds a predetermined threshold (e.g., 80%), the authentication means 15 authenticates the user. As described above, the memory 16 stores pre-registered user identification information and identification information of the authentication engines 30A, 30B, and 30C in association with the feature amounts of the user's facial image.
[0047] Then, when the authentication means 15 authenticates the user ("YES" in STEP 55), information related to the authentication result is transmitted from the processor 12 of the face authentication system 10 to the authentication engines 30A, 30B, and 30C via the communication unit 18 (STEP 56). Then, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C that have received the information related to the authentication result enable the respective processing units 40A, 40B, and 40C to implement the services corresponding to the authentication engines 30A, 30B, and 30C (STEP 57). Thereafter, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit information related to the usage status of the services to the face authentication system 10. As a result, information related to the usage status of services at each service provider is stored in the memory 16 for each user in the face authentication system 10.
[0048] On the other hand, if the feature amounts of the user's facial image received from the authentication engines 30A, 30B, 30C do not substantially match the feature amounts of the user's facial image stored in the memory 16 and the authentication means 15 is unable to authenticate the user ("NO" in STEP 55), information relating to the authentication result is sent from the processor 12 of the face authentication system 10 to the authentication engines 30A, 30B, 30C via the communication unit 18 (STEP 58). Then, the processors 32A, 32B, 32C of the authentication engines 30A, 30B, 30C that have received the information relating to the authentication result disable the implementation of the service corresponding to the authentication engine 30A, 30B, 30C via the respective processing units 40A, 40B, 40C (STEP 59). In this case, too, the processors 32A, 32B, and 32C of the authentication engines 30A, 30B, and 30C transmit information regarding the usage status of the service (specifically, information that the user attempted to be authenticated by the authentication engines 30A, 30B, and 30C but was not authenticated and was unable to use the service) to the face authentication system 10.
[0049] According to this authentication method, even if the features of a user's facial image are registered in an authentication engine of one service facility (e.g., authentication engine 30A) but not in an authentication engine of another service facility (e.g., authentication engine 30B), by storing the features of the user's facial image in association with the identification information of authentication engines 30A, 30B, and 30C in memory 16 of face authentication system 10, even a service facility that does not have the features of the user's facial image registered can authenticate the user by capturing the user's facial image with an imaging unit. In this case, the user does not need to register facial image data in all of the multiple authentication engines, thereby saving the user effort.
[0050] Next, a process will be described for a case where a user wants to increase the number of service providers to which the above-described facial authentication service is applied in the facial authentication system 10 shown in FIGS. 1 to 9 . After the user has performed the user registration described above, when the user presses the “Add Service” button with his / her finger on the initial screen of the user terminal 20 shown in FIG. 10 , a list of service providers is displayed as shown in FIG. 13 . Note that this list of service providers is pre-registered in the facial authentication system 10. On the screen shown in FIG. 13 , the icons of unregistered services and registered services are displayed in different colors, or the icons of unregistered services are displayed in a dimmed color, so that they can be distinguished from each other. When the user presses the icon of an unregistered service with his / her finger, the terms of the service to be added are displayed. When the user inputs an instruction to agree to the terms of the service, the unregistered service becomes a registered service. At this time, in the facial authentication system 10, the service provider related to this registered service is associated with the user ID (user identification information) and stored in the memory 16. After that, a captured screen of a face image as shown in FIG. 12 is displayed on the user terminal 20. When a user captures a facial image on such an imaging screen using the user terminal 20, the user's facial image data is transmitted from the user terminal 20 to the facial authentication system 10. In this way, the processor 12 of the facial authentication system 10 receives the facial image data from the user terminal 20. Then, based on the facial image data received from the user terminal 20, the processor 12 of the facial authentication system 10 extracts, as hash values, features of the facial image corresponding to the authentication engine of the new service provider using the feature extraction means 14. The processor 12 stores, by the registration means 13, the features of the facial image corresponding to the new authentication engine extracted by the feature extraction means 14 in the memory 16 of the facial authentication system 10 in association with the user ID (identification information of the user) and identification information of the authentication engine of the new service provider. In this way, the registration of the new service provider is completed.As will be described later, if the user's facial image data is stored in memory 16, when the user registers a new service provider using the user terminal 20, the feature extraction means 14 may extract, as a hash value, the features of the facial image corresponding to the authentication engine of the new service provider based on the user's facial image data stored in memory 16, without capturing the user's facial image using the user terminal 20. Also, the user may be able to delete a registered service on a screen such as that shown in FIG. 13. In this case, the registered service becomes an unregistered service. Furthermore, information stored in memory 16 relating to the features of the user's facial image corresponding to the authentication engine of the service provider related to the deleted registered service is deleted.
[0051] Furthermore, after the user has performed the user registration described above, when the user presses the "Authentication History" button with his / her finger on the initial screen of the user terminal 20 as shown in FIG. 10, a list of past authentication history information (in other words, a list of information related to the user's usage of the service provider) as shown in FIG. 14 is displayed on the user terminal 20. More specifically, the memory 16 of the face authentication system 10 stores the user's past authentication history information in association with the user's identification information. When the user presses the "Authentication History" button with his / her finger on the initial screen of the user terminal 20 as shown in FIG. 10, a signal requesting the user's past authentication history information is transmitted from the user terminal 20 to the processor 12 of the face authentication system 10. When the processor 12 of the face authentication system 10 receives the signal requesting the user's past authentication history information from the user terminal 20, the processor 12 transmits the past authentication history information corresponding to the user's identification information stored in the memory 16 to the user terminal 20 via the communication unit 18. As a result, the user terminal 20 displays a list of the user's past authentication history information. Furthermore, when the user presses a certain authentication history display with his / her finger in the list of past authentication history information as shown in FIG. 14, details of this authentication history are displayed on the user terminal 20 as shown in FIG.
[0052] Furthermore, in the present embodiment, instead of a user using the user terminal 20 to register the user's facial authentication features in the face authentication system 10, the user may use one of the authentication engines 30A, 30B, and 30C to register the user's facial authentication features in the face authentication system 10. Specifically, when a user inputs registration information into one of the authentication engines 30A, 30B, and 30C and captures the user's face image using the imaging units 38A, 38B, and 38C, the input registration information and the user's facial image data are transmitted from the authentication engines 30A, 30B, and 30C to the face authentication system 10. In this manner, the processor 12 of the face authentication system 10 receives the facial image data from the authentication engines 30A, 30B, and 30C. The processor 12 also issues a user ID as user identification information based on the registration information received from the authentication engines 30A, 30B, and 30C, and stores the issued user ID in the memory 16.
[0053] Next, the processor 12 of the face authentication system 10 extracts facial image features corresponding to each authentication engine 30A, 30B, and 30C as hash values using the feature extraction means 14 based on the facial image data received from the authentication engines 30A, 30B, and 30C. At this time, the feature extraction means 14 extracts the user's facial image features for each authentication engine 30A, 30B, and 30C. The feature extraction means 14 also extracts only the user's facial image features corresponding to the authentication engines 30A, 30B, and 30C of the service provider pre-selected by the user. For example, if the user is permitted to use facial image data for the service provider where authentication engine 30A is installed but is not permitted to use facial image data for the service provider where authentication engine 30B is installed, the feature extraction means 14 extracts only the user's facial image features corresponding to the authentication engine 30A. As described above, the memory 16 stores the user's identification information and the service provider selected by the user in association with each other. Then, the processor 12 causes the registration means 13 to store the facial image features corresponding to each authentication engine 30A, 30B, and 30C extracted by the feature extraction means 14 in the memory 16 of the face authentication system 10 in association with the user ID (user identification information) and the identification information of the authentication engines 30A, 30B, and 30C. In this manner, the registration of the user's facial images captured by the imaging units 38A, 38B, and 38C of the authentication engines 30A, 30B, and 30C is completed. In this manner, the user can register the facial authentication features of the user in the face authentication system 10 without using the user terminal 20.
[0054] According to the face authentication method performed by face authentication system 10 of the present embodiment having the above configuration, a user's face image data and user identification information are received, and feature quantities of the user's face image are extracted for each of the plurality of authentication engines 30A, 30B, and 30C based on the received user's face image data. Then, information related to the feature quantities of the user's face image for each of the plurality of authentication engines 30A, 30B, and 30C extracted is stored in memory 16 in association with the received user's identification information. According to this face authentication method, face authentication can be easily performed using the plurality of authentication engines 30A, 30B, and 30C.
[0055] Specifically, while the provision of an authentication engine using facial recognition has been widespread in the past, conventional facial recognition systems have been unable to perform facial recognition with an authentication engine in which facial data is not registered. Therefore, in order to perform authentication with each of multiple authentication engines, the user must register their facial data with each of the multiple authentication engines, which is time-consuming and stressful. In contrast, in the present embodiment, even if a user's facial image features are registered with an authentication engine (e.g., authentication engine 30A) of one service provider but not with an authentication engine (e.g., authentication engine 30B) of another service provider, the facial image features of the user are stored in memory 16 of facial recognition system 10 for each of authentication engines 30A, 30B, and 30C. Therefore, even with authentication engines 30A, 30B, and 30C of service providers in which the user's facial image features are not registered, the user can be authenticated by capturing the user's facial image with imaging units 38A, 38B, and 38C. In this case, the user does not need to register face image data in all of the multiple authentication engines 30A, 30B, and 30C, thereby saving the user time and effort. This makes it possible to encourage users who have not used various services that use authentication engines in which face image data is not registered, because registering face image data is troublesome, to use various services with ease.
[0056] Furthermore, when feature quantities of a user's facial image, such as a hash value, are extracted and stored in memory 16, the amount of data stored in memory 16 can be significantly reduced compared to when the user's facial image data itself is stored in memory 16. This is because the amount of data of the feature quantities of the user's facial image is smaller than the amount of data of the user's facial image data itself. In this case, the user's privacy can be more reliably protected because the user's facial image data itself is not stored in memory 16. Furthermore, when information related to the feature quantities of a user's facial image is sent between face authentication system 10 and each authentication engine 30A, 30B, 30C, the amount of data communication can be significantly reduced compared to when the user's facial image data is sent between face authentication system 10 and each authentication engine 30A, 30B, 30C.
[0057] Furthermore, in the face authentication method of the present embodiment, as described above, when extracting features of a user's face image based on the received face image data of the user, the features of the user's face image are extracted for each of the multiple authentication engines 30A, 30B, and 30C, and the extracted features of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C are stored in memory by the registration means 13 in association with the user's identification information. This can also handle cases where the features of the user's face image extracted by the feature extraction means 14 differ depending on the type of authentication engine 30A, 30B, and 30C. Note that if the same program is used in the multiple authentication engines 30A, 30B, and 30C and the features of the user's face image extracted by the feature extraction means 14 are common to the authentication engines 30A, 30B, and 30C, it is not necessary to extract the features of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C.
[0058] Furthermore, in the facial authentication method of the present embodiment, as described above, information related to the service provider selected by the user is stored in memory 16 in association with the user's identification information, and in the step of extracting features of the user's facial image for each of multiple authentication engines 30A, 30B, and 30C based on the received user's facial image data by feature extraction means 14, feature extraction means 14 extracts features of the user's facial image corresponding only to the authentication engines of the service providers selected by the user that are stored in memory 16. In this case, feature information of the user's facial image corresponding to authentication engines 30A, 30B, and 30C of service providers not selected by the user is not stored in memory 16, thereby improving security and reassuring the user. Furthermore, companies and the like that participate in the group of authentication engines collectively managed by facial authentication system 10 can appeal to customers by promoting the improved customer convenience of being able to be authenticated by multiple authentication engines simply by registering facial image data on user terminal 20 or the like.
[0059] Furthermore, in the face authentication method of this embodiment, as described above, the feature extraction means 14 extracts a hash value calculated from the received face image data of the user using a predetermined hash function as a feature of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C. In this case, the hash value is stored in memory 16 as a feature of the user's face image, so the amount of data stored in memory 16 can be reduced compared to when the face image data itself is stored in memory 16. Furthermore, since it is difficult to restore or infer face image data from the hash value, face authentication system 10 stores only the hash value, which can improve user privacy and security.
[0060] In this embodiment, the feature extraction means 14 is not limited to extracting the feature of the user's facial image as a hash value for each of the authentication engines 30A, 30B, and 30C based on the received user's facial image data. The feature extraction means 14 may also extract the feature of the user's facial image as a value of a type other than a hash value for each of the authentication engines 30A, 30B, and 30C based on the received user's facial image data. For example, the relative position, size, shape, etc. of each facial feature (eyes, nose, ears, etc.) may be extracted as the feature of the user's facial image. Even in this case, if the amount of data of the value of a type other than a hash value is smaller than the amount of data of the facial image itself, the amount of data stored in memory 16 can be reduced.
[0061] Furthermore, in the face authentication method of the present embodiment, as described above, in the step of extracting feature amounts of a user's facial image for each of the plurality of authentication engines 30A, 30B, and 30C based on received facial image data of the user by the feature extraction means 14, the feature amounts of the user's facial image for each of the plurality of authentication engines 30A, 30B, and 30C are extracted by the feature extraction means 14 based on the user's facial image data transmitted from the user terminal 20 carried by the user. Alternatively, in the step of extracting feature amounts of a user's facial image for each of the plurality of authentication engines 30A, 30B, and 30C based on received facial image data of the user by the feature extraction means 14, the feature amounts of the user's facial image for each of the plurality of authentication engines 30A, 30B, and 30C may be extracted by the feature extraction means 14 based on the user's facial image data transmitted from one of the plurality of authentication engines 30A, 30B, and 30C.
[0062] Furthermore, this embodiment uses a program executed by the processor 12 for performing a face authentication method using the face authentication system 10, and a recording medium on which this program is recorded. Here, by executing the program, the processor 12 receives a user's face image data and the user's identification information, and extracts feature quantities of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C based on the received user's face image data. Then, information related to the extracted feature quantities of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C is stored in memory 16 in association with the received user's identification information. Using this program and recording medium, face authentication can be easily performed using the multiple authentication engines 30A, 30B, and 30C.
[0063] Furthermore, this embodiment uses a face authentication system 10 including a processor 12. In this face authentication system 10, the processor 12 executes a program to receive face image data and user identification information of a user, and extracts features of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C based on the received face image data of the user. Then, information related to the extracted features of the user's face image for each of the multiple authentication engines 30A, 30B, and 30C is stored in memory 16 in association with the received user identification information. According to this face authentication system 10, face authentication can be easily performed using the multiple authentication engines 30A, 30B, and 30C.
[0064] The face authentication method and face authentication system according to the present invention are not limited to the above-described aspects, and various modifications can be made.
[0065] For example, a facial authentication system as shown in FIG. 16 may be used. The facial authentication system 50 shown in FIG. 16 includes a processor 52, a first server 56, a second server 58, and a third server 60. Here, the servers 56, 58, and 60 correspond to the authentication engines 30A, 30B, and 30C, respectively. Specifically, the first server 56 corresponds to the authentication engine 30A, the second server 58 corresponds to the authentication engine 30B, and the third server 60 corresponds to the authentication engine 30C. Although FIG. 16 illustrates three authentication engines 30A, 30B, and 30C, when two or four or more authentication engines are used, a server corresponding to each authentication engine is provided in the facial authentication system 10. The processor 52 also includes a server management means 52a, a feature extraction means 54, a registration means 53, and an authentication means 55. The feature extraction means 54, registration means 53, and authentication means 55 of the processor 52 have substantially the same functions as the feature extraction means 14, registration means 13, and authentication means 15 of the processor 12 of the face authentication system 10 shown in Figures 1, 4, and 7. The server management means 52a manages the servers 56, 58, and 60.
[0066] Each server 56, 58, 60 stores feature quantities of facial image data of a user corresponding to each authentication engine 30A, 30B, 30C, associated with the user's identification information. Each server 56, 58, 60 is communicatively connected to the corresponding authentication engine 30A, 30B, 30C via a network such as the Internet. Each server 56, 58, 60 is configured to be collectively managed by the server management means 52a using an API (Application Programming Interface). This makes it easier to configure the systems of each server 56, 58, 60 than if the systems (programs) of each server 56, 58, 60 were configured independently. Furthermore, the server management means 52a and the service providers at which the authentication engines 30A, 30B, 30C are installed are API-linked. For example, the platform of the server management means 52a may be opened to each service provider, and each service provider may use the same platform as the server management means 52a, thereby easily building a system for providing services at each service provider.
[0067] A face authentication system 50 having such a processor 52 and each of the servers 56, 58, and 60 can also perform processing similar to that of the face authentication system 10 having the processor 12. That is, according to the face authentication method performed by the face authentication system 50 shown in Fig. 16, the processor 52 extracts features of the user's face image for each of the authentication engines 30A, 30B, and 30C based on the received face image data of the user using feature extraction means 54, and stores the extracted features of the user's face image in each of the servers 56, 58, and 60 in association with the user's identification information and the authentication engines 30A, 30B, and 30C using registration means 53.
[0068] Furthermore, information related to the features of the user's facial image stored in each server 56, 58, 60 is transmitted from each server 56, 58, 60 to the corresponding authentication engine 30A, 30B, 30C. As a result, when authenticating a user in each authentication engine 30A, 30B, 30C, the user's facial image data is acquired by capturing an image of the user using the imaging units 38A, 38B, 38C, and the features of the user's facial image are extracted by the feature extraction means 34A, 34B, 34C based on the acquired facial image data, thereby enabling each authentication engine 30A, 30B, 30C to authenticate the user. Thereafter, the processors 32A, 32B, 32C of the authentication engines 30A, 30B, 30C transmit information related to the service usage status to the face authentication system 10. As a result, information related to the service usage status at each service provider in the face authentication system 50 is stored in each server 56, 58, 60 for each user.
[0069] As another method for authenticating a user, when authenticating a user in each authentication engine 30A, 30B, 30C, the user's facial image data is acquired by capturing an image of the user using the imaging units 38A, 38B, 38C, and feature extraction means 34A, 34B, 34C extracts features of the user's facial image based on the captured facial image data. Then, information related to the features of the user's facial image is transmitted from each authentication engine 30A, 30B, 30C to the face authentication system 50. This enables user authentication by the authentication means 55. The user authentication result is then transmitted from the face authentication system 50 to the original authentication engine 30A, 30B, 30C.
[0070] As another method for authenticating a user, when authenticating a user in each authentication engine 30A, 30B, 30C, the user's facial image data is acquired by capturing an image of the user using the imaging units 38A, 38B, 38C. The user's facial image data is then transmitted from each authentication engine 30A, 30B, 30C to the face authentication system 50. The processor 52 then extracts features of the user's facial image based on the user's facial image data transmitted to each server 56, 58, 60 using feature extraction means 54, and compares the extracted features of the user's facial image with the features of the user's facial image stored in each server 56, 58, 60 using authentication means 55. This enables the authentication means 55 to authenticate the user. The user authentication result is then transmitted from the face authentication system 50 to the original authentication engine 30A, 30B, 30C.
[0071] According to these face authentication methods, face authentication can be easily performed using a plurality of authentication engines 30A, 30B, and 30C.
[0072] In addition, in the face authentication system 10 shown in Figures 1, 4, 7, etc., the processor 12 may store the user's face image data itself transmitted from the user terminal 20 and each authentication engine 30A, 30B, 30C in the memory 16.
[0073] Furthermore, in the above example, the face authentication systems 10 and 50 are installed separately from the authentication engines 30A, 30B, and 30C installed at each service facility, but one of the authentication engines 30A, 30B, and 30C installed at each service facility may also have the functions of the face authentication systems 10 and 50. That is, the processor of one of the authentication engines 30A, 30B, and 30C installed at each service facility may have feature extraction means, registration means, and authentication means that have functions equivalent to the feature extraction means 14, registration means 13, and authentication means 15 in the processor 12 of the face authentication system 10 shown in Figures 1, 4, 7, etc. [Explanation of symbols]
[0074] 10. Facial Recognition System 12 processors 13 Registration Method 14 Feature extraction method 15 Authentication Methods 16 memory 18 Communications Department 20 User terminal 30A, 30B, 30C Certified Engines 32A, 32B, and 32C processors 34A, 34B, 34C Feature extraction means 35A, 35B, 35C Authentication Methods 36A, 36B, 36C Memory 38A, 38B, 38C Imaging unit 40A, 40B, 40C Processing section 42A, 42B, 42C Communication Department 50 Facial Recognition System 52 processors 52a Server Management Methods 53 Registration Method 54 Feature extraction method 55 Authentication Methods 56 First Server 58 Second Server 60 Third Server
Claims
1. a first image capturing means for capturing and transmitting facial image data of a user for extracting features to be used as a comparison standard; a plurality of face authentication devices that compare the user's face with the comparison criteria and determine whether or not to provide the service requested by the user; a service registration means for registering a service to be used by a user from among the services provided using each of the face authentication devices; the first photographing means and the service registration means are provided using a user terminal which is an information terminal possessed by a user, Each of the face authentication devices has a feature extraction means for extracting features from the face image data of the user, and a storage device in which the feature used as the comparison standard is registered. Authentication system.
2. a first image capturing means for capturing and transmitting facial image data of a user for extracting features to be used as a comparison standard; a plurality of face authentication devices that compare the user's face with the comparison standard and determine whether or not to provide the service requested by the user; Each of the face authentication devices has a feature extraction means for extracting a feature from the face image data of the user, and a storage device in which the feature used as the comparison standard is registered, The services include those that can be provided by only authenticating the user's face, and those that require authentication by a method other than biometric authentication in addition to authenticating the user's face. Authentication system.
3. The face recognition devices each operate differently when the face recognition of the user is successful, and the details of the processing are different depending on the device.
3. The authentication system according to claim 1 or 2.
4. Each of the face recognition devices is installed in a service facility that is a facility where services are provided using these face recognition devices.
3. The authentication system according to claim 1 or 2.
5. Each of the face authentication devices independently determines whether or not to provide the service requested by the user.
3. The authentication system according to claim 1 or 2.
6. The facial recognition devices have different extraction specifications for feature amounts from facial image data.
3. The authentication system according to claim 1 or 2.
7. The authentication means of each face authentication device is aggregated, and a server device that performs centralized user identity verification is not provided.
10. The authentication system of claim 1, 2, or 6.
8. At least one of the face authentication devices can generate and register features to be used as the comparison standard even from a face image acquired by a photographing means provided in the face authentication device.
3. The authentication system according to claim 1 or 2.
9. At least one of the facial authentication devices authenticates a user to perform a payment transaction, and the facial authentication device or the payment transaction requires the user to authenticate by another method in addition to authenticating the user's face.
3. The authentication system according to claim 1 or 2.
10. At least one of the face recognition devices is a second photographing means which is a photographing means provided in the face authentication device; an authentication server connected to the second photographing means via the Internet, the authentication server has means for extracting features from face image data and means for authenticating a user; the second photographing means transmits the acquired face image data of the user to the authentication server; 3. The authentication system according to claim 1 or 2.
11. Each of the face authentication devices has a second photographing means for photographing a face of a user.
3. The authentication system according to claim 1 or 2.
Citation Information
Patent Citations
Intercom, and ringtone control method of intercom
JP2007184839A
Position authentication device, terminal, position authentication method and program
JP2016025386A
Id provider recommendation apparatus, id recommendation system, and id provider recommendation method
JP2016045633A
Service system and robot
JP2017209769A
Information processing apparatus, information processing method, and computer program
JP2019062394A